CVE-2006-4602

Tikiwiki Cms/groupware - Unrestricted File Upload

Title source: rule

Description

Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16885
exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/2288
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/tikiwiki_jhot_exec.rb

Scores

EPSS 0.8336
EPSS Percentile 99.3%

Details

Status published
Products (1)
tiki/tikiwiki_cms\/groupware 1.9.4
Published Sep 07, 2006
Tracked Since Feb 18, 2026